CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3336

As cited

Copy frozen at (site build).

threat intel

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

Iranian state-backed group Nimbus Manticore conducted attacks across the Middle East, Africa, and South Asia using a previously undocumented Windows backdoor named NightLedger and custom WebSocket tunnelers. The campaign demonstrates the group's capability to deploy new malware variants for command and control operations.

Why it matters: Organizations in the Middle East, Africa, and South Asia should review endpoint detection logs for NightLedger and WebSocket tunneler activity, as this group actively targets regional entities with novel malware.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

Iranian state-backed group Nimbus Manticore conducted attacks across the Middle East, Africa, and South Asia using a previously undocumented Windows backdoor named NightLedger and custom WebSocket tunnelers. The campaign demonstrates the group's capability to deploy new malware variants for command and control operations.

Why it matters: Organizations in the Middle East, Africa, and South Asia should review endpoint detection logs for NightLedger and WebSocket tunneler activity, as this group actively targets regional entities with novel malware.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary